{"schema_version":1,"assessment_id":"eoa_inverse_innovation_exp03_opportunity320_20260801","source_experiment_id":"eoa_inverse_innovation_exp03_full320_20260801","cell_id":"layer_decay_and_expiration_management__computer_science","archetype_slug":"layer_decay_and_expiration_management","domain_slug":"computer_science","title":"Dependency-Gated Lifecycle Management for Superseded CI Artifacts","opportunity_summary":"Evaluate a policy-governed registry lifecycle that classifies superseded artifacts, applies holds and dependency vetoes, archives retained history, quarantines deletion candidates, publishes tombstones, and verifies restoration before any later destruction. The candidate aims to reduce active stale bytes and obsolete-artifact discoverability relative to age-only cleanup without impairing rollback, provenance, compliance, or incident reconstruction. Local problem magnitude, acceptance thresholds, effectiveness, and distinctiveness remain unverified.","adopter_authorizer":"The registry owner would operate the system under policy approved by release engineering and security; compliance or legal authorities control applicable holds, while service owners review unresolved deployment, rollback, and external-reference dependencies.","scores":{"meaningful_impact":{"score":4,"rationale":"The proposal addresses storage and stale-selection burdens while protecting rollback, provenance, compliance, and incident reconstruction, so successful intervention could affect several operationally important objectives. The amount of superseded material and realized harm in any registry are not established."},"stakeholder_pull":{"score":3,"rationale":"Release engineers, service owners, registry operators, security, incident response, compliance, legal, and audit stakeholders have recognizable interests in the stated tradeoff. The packet supplies no evidence of expressed demand, budget commitment, incidents, or adoption requests."},"incremental_advantage":{"score":4,"rationale":"Relative to fixed-age or untagged-only garbage collection, the candidate adds retention classes, authority-controlled holds, dependency vetoes, reversible quarantine, tombstones, archive restoration tests, and recorded disposition decisions. Whether these additions improve outcomes enough to justify operator effort is explicitly left to comparative testing."},"distinctiveness_plausibility":{"score":3,"rationale":"The mechanism composition is differentiated from the stated age-only rival through policy, dependency, restoration, and authority controls, making a distinct testable configuration plausible. Relevant registry retention, soft-deletion, archival, attestation, and garbage-collection prior art is unsearched, so distinctiveness beyond that rival is unverified."},"technical_implementability":{"score":4,"rationale":"The candidate identifies artifact-level state, a staged lifecycle, measurable outcomes, a bounded namespace, quarantine, restoration tests, and rollback procedures that support implementation. Hidden digest consumers, shared blobs, incomplete dependency graphs, hold integration, and cold-tier recovery remain material technical constraints."},"adoption_authority_feasibility":{"score":4,"rationale":"Execution, policy approval, holds, and dependency review are assigned to identifiable authorities, and the first step is confined to a nonproduction namespace without hard deletion. Feasibility is reduced by required coordination across registry, release, security, service-owner, compliance, and legal roles."},"evidence_readiness":{"score":4,"rationale":"A 30-day, at-most-500-artifact pilot, an age-only comparator, observable state, explicit falsifiers, restore tests, and halt conditions provide a strong evidence structure. Artifact-class acceptance bounds, recovery objectives, baseline measurements, and dependency-coverage criteria still must be set locally."},"safety_net_benefit":{"score":5,"rationale":"The proposed first step prohibits hard deletion, preserves holds, blocks dependency-unclear candidates, uses reversible quarantine and archive restoration tests, and specifies halt and restoration responses to missed references, fidelity failures, excessive restore failures, or attempted deployment."},"scalability":{"score":3,"rationale":"The lifecycle logic can in principle be repeated across namespaces and artifact classes, but scaling reliable reference discovery, shared-blob accounting, external-digest visibility, hold governance, restoration testing, tombstone maintenance, and service-owner review is unresolved."}},"score_confidence":"MODERATE","costs":{"first_evidence":{"band_2026_usd":"10K_TO_50K","scope":"Prepare and run the specified 30-day nonproduction pilot on no more than 500 superseded artifacts, including inventory, baseline age-only comparison, dependency checks, sample archival, quarantine, restore and fidelity tests, operator-effort tracking, and results review.","confidence":"MODERATE","assumptions":["Existing registry APIs and a nonproduction namespace are available.","No production artifacts are hard-deleted.","The pilot uses existing staff and infrastructure rather than developing a production-grade platform.","Acceptance thresholds and recovery objectives can be agreed within the pilot preparation period.","External reference discovery is assessed but not assumed complete."]},"initial_deployment_startup":{"band_2026_usd":"50K_TO_250K","scope":"Develop and integrate lifecycle-state automation, policy and hold controls, dependency vetoes, archival and restoration workflows, tombstone and audit records, monitoring, access controls, and operator procedures for an initial controlled production scope.","confidence":"LOW","assumptions":["The organization has a registry with usable metadata and integration APIs.","Existing archival storage, identity, logging, and deployment systems can be integrated.","Deployment begins with a limited set of artifact classes or namespaces.","No major registry replacement or comprehensive reconstruction of organization-wide dependency data is required.","Security, compliance, legal, and service-owner reviews are included."]},"operational_launch":{"band_2026_usd":"50K_TO_250K","scope":"Validate production readiness, backfill metadata, configure artifact-class policies and holds, train operators and service owners, test incident and rollback procedures, stage rollout across selected production namespaces, and evaluate launch outcomes.","confidence":"LOW","assumptions":["The bounded pilot meets preset benefit and safety criteria.","Initial deployment components are reusable for launch.","The launch remains limited rather than organization-wide.","Dependency visibility is sufficient for quarantine decisions, with ambiguous cases retained.","Cold-tier restoration can be tested without disrupting live services."]},"annual_recurring":{"band_2026_usd":"10K_TO_50K","scope":"Operate policy reviews, exception and hold management, dependency monitoring, periodic restore tests, audit-record retention, tombstone maintenance, incident handling, software upkeep, and outcome reporting for a limited deployment.","confidence":"LOW","assumptions":["Most lifecycle processing is automated after startup.","Archive storage and retrieval volumes are moderate.","Manual review is concentrated on exceptions and unresolved dependencies.","The estimate excludes unusually large registries, frequent legal holds, major compliance certification, and high-volume archive retrieval.","Storage savings are not netted against operating resources."]}},"research_burden":"MODERATE","earliest_credible_horizon":"0_TO_3_MONTHS","pipeline_gates":{"recognizable_externally_supportable_problem":{"status":"YES","reason":"The candidate defines observable superseded artifacts, stale discoverability or deployability, storage and search burdens, and concrete risks from both indefinite retention and indiscriminate deletion. Local prevalence and magnitude still require inventory evidence, but the problem itself is externally testable."},"identifiable_adopter_or_authorizer":{"status":"YES","reason":"The registry owner is identified as operator, release engineering and security as policy approvers, compliance or legal authorities as hold controllers, and service owners as reviewers of unresolved dependencies."},"distinct_testable_incremental_claim":{"status":"YES","reason":"The candidate can be compared with age-only cleanup on active stale bytes, obsolete discoverability, missed dependencies, archive recoverability, policy violations, and operator effort; failure to improve these outcomes within preset bounds falsifies the incremental claim."},"bounded_next_evidence_step":{"status":"YES","reason":"The packet authorizes a 30-day pilot in one nonproduction namespace covering at most 500 superseded artifacts, with sample archival, dependency-clear quarantine, restore tests, and no hard deletion."},"no_unresolved_safety_or_authority_stop":{"status":"YES","reason":"For the bounded evidence step, hard deletion, hold overrides, score-based orphan assumptions, and deletion under incomplete dependency visibility are prohibited. Quarantine is reversible, authorities are separated, and explicit halt and restoration conditions are supplied."},"implementation_cost_scope_and_range":{"status":"YES","reason":"The candidate defines enough of the pilot and lifecycle components to bound broad resource-equivalent cost bands, although production costs remain low-confidence because registry scale, integration quality, dependency visibility, compliance requirements, and archive volumes are unspecified."}},"blocking_evidence":["A bounded inventory must establish material superseded-artifact accumulation, stale discoverability or selection exposure, or a meaningful storage, search, maintenance, or retention conflict.","Artifact-class acceptance bounds must be set for stale-byte reduction, obsolete discoverability, dependency misses, restoration fidelity and latency, policy violations, operator effort, and rollback risk.","Dependency discovery must demonstrate adequate coverage of deployments, manifests, shared blobs, rollback systems, provenance systems, and known external digest consumers for the tested scope.","Hold data and authority workflows must reliably prevent quarantine or later destruction where legal, compliance, investigation, or release obligations apply.","Archive restoration must meet agreed digest, fidelity, and recovery objectives for the tested sample.","The comparative pilot must show an advantage over age-only cleanup without exceeding preset harm, compliance, or effort bounds."],"next_evidence_step":"Run the authorized 30-day nonproduction pilot on at most 500 superseded artifacts after presetting artifact-class acceptance bounds: compare dependency-gated lifecycle management with an age-only eligibility baseline on active stale bytes, obsolete discoverability, dependency blocks or misses, restore fidelity and latency, policy violations, and operator effort. Archive a defined sample, quarantine only dependency-clear candidates, prohibit hard deletion, and reject the intervention if it fails to reduce stale bytes or discoverability or performs worse on any preset safety or effort bound.","research_questions":["Does the bounded namespace contain material superseded-artifact accumulation or obsolete discoverability relative to current required artifacts?","Which deployment, rollback, provenance, manifest, shared-blob, and external-digest references can be observed, and what reference classes remain hidden?","What artifact-specific retention classes, rollback windows, recovery objectives, and acceptance bounds are justified by local service criticality and compliance obligations?","Compared with age-only cleanup, does the composition reduce active stale bytes and obsolete discoverability without increasing missed dependencies, restore failures, policy violations, or operator effort beyond preset bounds?","Can compliance, legal, investigation, and release holds be represented accurately and exercised as authoritative vetoes?","Do archive restores preserve digest and artifact fidelity and meet the agreed recovery-time objective across the sampled artifact classes?","How often do tombstones, exception holds, and manual reviews themselves become persistent operational burdens?","Which relevant registry retention, garbage-collection, archival-restoration, soft-deletion, provenance, and artifact-attestation systems already implement some or all of this composition?"],"recommendation":"PILOT_NOW","uncertainty_constraints":["Problem prevalence and magnitude are unsupported until a local inventory is performed.","Stakeholder pull is inferred from assigned responsibilities; no expressed demand or resource commitment is supplied.","Pilot thresholds and recovery objectives are not instantiated in the sealed candidate.","Dependency completeness is uncertain, especially for shared blobs and external consumers holding digests.","Sampled restore success cannot establish recoverability of all archived artifacts.","Production integration effort, compliance burden, registry scale, archive volume, and recurring exception workload are unspecified.","Incremental advantage over age-only cleanup is a hypothesis requiring the stated comparison.","World novelty, prior-art overlap, market size, and realized impact are unmeasured."],"closed_book_prior_art_boundary":"Prior art is unsearched and unverified in this closed-book assessment. No claim is made about novelty, prevalence, market position, or whether registry retention, garbage-collection, archival-restoration, soft-deletion, provenance, or attestation systems already contain the proposed mechanisms."}